CVE-2026-63448: Oisf Suricata
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one direction, including async-oneside flows, because cleanup waits for inspection in the unseen direction. The transaction creation paths in rust/src/smb can exceed the intended SMB_MAX_TX bound, and cleanup repeatedly scans the growing list. Sustained one-directional SMB traffic can therefore cause unbounded per-flow state and CPU and memory exhaustion. This issue is fixed in versions 8.0.6 and 7.0.17.
Affected products
- Oisf Suricata: before 7.0.17 (fixed in 7.0.17); from 8.0.0, before 8.0.6 (fixed in 8.0.6)
Published 2026-09-18. Last modified 2026-09-28.